Skip to content
Victorem

How we protect your information

Security at Victorem Performance Nutrition

When you work with Victorem, you trust us with information about your health, your training, and your goals. Protecting that information is a responsibility we designed the platform around from the start. Here is how we do it, in plain language.

Built on Google Cloud

The Victorem platform runs entirely on Google Cloud, in data centers located in the United States. That infrastructure is independently certified against rigorous industry standards, including SOC 2 Type II and ISO 27001.

Encryption everywhere

All data is encrypted in transit using TLS 1.2 or higher — enforced, not optional — and encrypted at rest with AES-256. Sensitive credentials such as sign-in tokens, password reset links, and invitation links are stored only as one-way cryptographic hashes, so they never sit in our database in usable form.

Your account is protected

Client accounts come with strong protections switched on automatically — nothing to configure, nothing to opt into:

  • Signing in from a new device requires a verification code sent to your email — on every account, automatically.
  • Sessions expire after 24 hours of inactivity.
  • Repeated failed sign-in attempts are throttled.
  • A password quality screen blocks weak and commonly used passwords.
  • Changing your password immediately signs out every other device.

Every access is recorded

Every view of a client record — by our staff or through the client portal and mobile app — is written to a tamper-evident audit log that can never be edited or deleted, and is retained permanently. If your record is opened, there is a permanent trace of it.

Telehealth on our own infrastructure

Video sessions run on Victorem’s own encrypted telehealth service, inside the same protected Google Cloud environment as the rest of the platform. No third-party video vendor ever handles your session media.

AI with a clinician in charge

The platform’s AI features run on Google’s Vertex AI, under the same healthcare agreement that covers the rest of the platform, and your data is never used to train AI models. Every AI-drafted note or suggestion is reviewed and approved by your dietitian before it becomes part of your record, and AI actions always require explicit human approval.

Payments

Payments are processed by Stripe, a PCI DSS Level 1 payment processor. Your card details are stored in Stripe’s secure vault — never on Victorem’s servers.

Always recoverable

The platform’s database is protected by continuous point-in-time backups plus 30 days of daily backups, so your records stay intact even if something goes wrong.

Ongoing vigilance

Security is not a one-time setup. Every code change runs through automated dependency vulnerability scanning, and we conduct recurring in-depth security reviews across authentication, authorization, file storage, and AI boundaries.

Report a concern

If you believe you’ve found a vulnerability, we want to hear from you and will respond quickly. Email [email protected].

For how these safeguards meet our obligations as a healthcare practice, see our Compliance page. Our Privacy Policy and Terms cover the rest of our online services.